Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

spring-cloud-starter-netflix-eureka-client:4.1 has vulnerability with dependency commons-jxpath:1.3 #4341

Open
ziad-saade opened this issue Sep 30, 2024 · 3 comments
Labels
dependencies Pull requests that update a dependency file

Comments

@ziad-saade
Copy link

ziad-saade commented Sep 30, 2024

No description provided.

@ziad-saade
Copy link
Author

image
spring-cloud-starter-netflix-eureka-client latest version 4.1.3
image
commons-jxpath latest version 1.3
image

@ziad-saade ziad-saade changed the title spring-cloud-starter-netflix-eureka-client:4.1commons-jxpath hav vlunarblitiy issues spring-cloud-starter-netflix-eureka-client:4.1 has vulnerability with dependency commons-jxpath:1.3 Sep 30, 2024
@OlgaMaciaszek
Copy link
Collaborator

Hello, @ziad-saade, thanks for reporting the issue. This is a transitive dependency provided by an external repo: https://github.com/Netflix/netflix-commons. There's no higher version of Netflix/Eureka that we could upgrade to. We can't also provide a fix for Netflix/Eureka, since no higher version of Netflix/netflix-commons is available. The users can exclude the dependency on their end. Please create an issue in Netflix/netflix-commons and link here. We'll upgrade once an upgraded version is made available.

@OlgaMaciaszek OlgaMaciaszek added dependencies Pull requests that update a dependency file and removed waiting-for-triage labels Sep 30, 2024
@ziad-saade
Copy link
Author

ziad-saade commented Sep 30, 2024

Thanks you @OlgaMaciaszek for your reply, below link to the issue:
Netflix/netflix-commons#34

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

No branches or pull requests

2 participants